Controls
Structuring the 93 controls of ISO 27002 sensibly
Organisational, people, physical and technological: the four themes help with responsibility and evidence management.
7 minute read · Content as of 21.07.2026
Controls are not standalone projects
Many controls already live in procurement, HR, IT operations, development or facility management. The ISMS does not have to duplicate these services; it has to connect requirements, responsibilities and evidence of effectiveness.
Assign owners and evidence first
The fastest reality check is not asking whether a control is supposedly implemented. Ask who operates it, what outcome is expected and what current evidence is available.
- Organisational controls: governance, suppliers, incidents, continuity
- People controls: joining, role changes, awareness, leaving
- Physical controls: entry, sites, equipment, environmental risks
- Technological controls: identities, cryptography, logging, development
Attributes support your own view
ISO/IEC 27002 offers attributes that let you group controls by security function or protection goal, for example. Use this view for reports without losing the unique control ID as the shared reference.
Sources used
- ISO/IEC 27002:2022 · ISO · 2022
- ISMS practice patterns · KaitoSec